# Restricting queries to certain nodes only

**URL:** <https://discuss.elastic.co/t/restricting-queries-to-certain-nodes-only/9614>\
**Category:** Elasticsearch\
**Created:** [November 7, 2012, 11:47pm UTC](https://discuss.elastic.co/t/restricting-queries-to-certain-nodes-only/9614 "2012-11-07T23:47:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_5](https://avatars.discourse-cdn.com/v4/letter/m/b3f665/32.png) [@Matt\_5](https://discuss.elastic.co/u/Matt_5)\
**Post date:** [November 7, 2012, 11:47pm UTC](https://discuss.elastic.co/t/restricting-queries-to-certain-nodes-only/9614/1 "2012-11-07T23:47:37Z")

</div>

Hi Everyone,

I am hoping to utilize Elasticsearch for our search needs, but I had a few  
questions about a particular infrastructure issue that I wasn’t able to get  
resolved by looking through the various Elasticsearch documentation and  
resources.

The issue is that we have both a datacenter and an internal corporate  
network. Let’s say that the Elasticsearch nodes are as follows:

Internal LAN: _Node 1_  
Datacenter: _Node 2 & Node 3_

We wish that it work in such a way that search queries that are executed on  
the LAN only go to Node 1 (these would be search requests from within the  
company). However, queries executed from web servers in the datacenter  
should only go to Nodes 2 and 3. Node 1 will be able to communicated to the  
other 2 via a VPN, but we wish to minimize traffic on it (for obvious  
reasons); this means that we don’t want a situation where a large amount of  
web requests trigger many queries on the node inside the LAN (Node 1).

Is it possible to restrict queries to servers in some way that would  
accommodate our needs? We still want the nodes to communicate with each  
other as needed for Elasticsearch to function properly, and be highly  
available by way of replicas, but the idea is to minimize heavy traffic  
over bottlenecks (namely the VPN in this case).

I apologize if this question was already asked before, but I wasn't able to  
find it. Thank you in advance! =)

-- Matt

--

---

<div class="post-metadata">

**Author:** ![Igor\_Motov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/igor_motov/32/45193_2.png) [@Igor\_Motov](https://discuss.elastic.co/u/Igor_Motov)\
**Post date:** [November 8, 2012, 3:38am UTC](https://discuss.elastic.co/t/restricting-queries-to-certain-nodes-only/9614/2 "2012-11-08T03:38:59Z")

</div>

The only solution that comes to mind is to make sure that all nodes have  
all shards (by setting number\_of\_replicas to 2), execute all queries with  
preference[http://www.elasticsearch.org/guide/reference/api/search/preference.html](http://www.elasticsearch.org/guide/reference/api/search/preference.html) set  
to "\_local", and make sure that internal users only connect to Node 1 and  
external users are load balanced between Node 2 and Node 3. Unfortunately,  
this solution will not scale if you will ever have more data than you can  
fit into a single node.

On Wednesday, November 7, 2012 6:47:38 PM UTC-5, Matt wrote:

> Hi Everyone,
> 
> I am hoping to utilize Elasticsearch for our search needs, but I had a few  
> questions about a particular infrastructure issue that I wasn’t able to get  
> resolved by looking through the various Elasticsearch documentation and  
> resources.
> 
> The issue is that we have both a datacenter and an internal corporate  
> network. Let’s say that the Elasticsearch nodes are as follows:
> 
> Internal LAN: _Node 1_  
> Datacenter: _Node 2 & Node 3_
> 
> We wish that it work in such a way that search queries that are executed  
> on the LAN only go to Node 1 (these would be search requests from within  
> the company). However, queries executed from web servers in the datacenter  
> should only go to Nodes 2 and 3. Node 1 will be able to communicated to the  
> other 2 via a VPN, but we wish to minimize traffic on it (for obvious  
> reasons); this means that we don’t want a situation where a large amount of  
> web requests trigger many queries on the node inside the LAN (Node 1).
> 
> Is it possible to restrict queries to servers in some way that would  
> accommodate our needs? We still want the nodes to communicate with each  
> other as needed for Elasticsearch to function properly, and be highly  
> available by way of replicas, but the idea is to minimize heavy traffic  
> over bottlenecks (namely the VPN in this case).
> 
> I apologize if this question was already asked before, but I wasn't able  
> to find it. Thank you in advance! =)
> 
> -- Matt

--

---

<div class="post-metadata">

**Author:** ![Matt\_5](https://avatars.discourse-cdn.com/v4/letter/m/b3f665/32.png) [@Matt\_5](https://discuss.elastic.co/u/Matt_5)\
**Post date:** [November 8, 2012, 6:07pm UTC](https://discuss.elastic.co/t/restricting-queries-to-certain-nodes-only/9614/3 "2012-11-08T18:07:31Z")

</div>

Thanks! We'll try this on some development servers and see how it works.

-- Matt

On Wednesday, November 7, 2012 9:38:59 PM UTC-6, Igor Motov wrote:

> The only solution that comes to mind is to make sure that all nodes have  
> all shards (by setting number\_of\_replicas to 2), execute all queries with  
> preference[http://www.elasticsearch.org/guide/reference/api/search/preference.html](http://www.elasticsearch.org/guide/reference/api/search/preference.html) set  
> to "\_local", and make sure that internal users only connect to Node 1 and  
> external users are load balanced between Node 2 and Node 3. Unfortunately,  
> this solution will not scale if you will ever have more data than you can  
> fit into a single node.
> 
> On Wednesday, November 7, 2012 6:47:38 PM UTC-5, Matt wrote:
> 
> > Hi Everyone,
> > 
> > I am hoping to utilize Elasticsearch for our search needs, but I had a  
> > few questions about a particular infrastructure issue that I wasn’t able to  
> > get resolved by looking through the various Elasticsearch documentation and  
> > resources.
> > 
> > The issue is that we have both a datacenter and an internal corporate  
> > network. Let’s say that the Elasticsearch nodes are as follows:
> > 
> > Internal LAN: _Node 1_  
> > Datacenter: _Node 2 & Node 3_
> > 
> > We wish that it work in such a way that search queries that are executed  
> > on the LAN only go to Node 1 (these would be search requests from within  
> > the company). However, queries executed from web servers in the datacenter  
> > should only go to Nodes 2 and 3. Node 1 will be able to communicated to the  
> > other 2 via a VPN, but we wish to minimize traffic on it (for obvious  
> > reasons); this means that we don’t want a situation where a large amount of  
> > web requests trigger many queries on the node inside the LAN (Node 1).
> > 
> > Is it possible to restrict queries to servers in some way that would  
> > accommodate our needs? We still want the nodes to communicate with each  
> > other as needed for Elasticsearch to function properly, and be highly  
> > available by way of replicas, but the idea is to minimize heavy traffic  
> > over bottlenecks (namely the VPN in this case).
> > 
> > I apologize if this question was already asked before, but I wasn't able  
> > to find it. Thank you in advance! =)
> > 
> > -- Matt

--

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:05am UTC](https://discuss.elastic.co/t/restricting-queries-to-certain-nodes-only/9614/4 "2017-07-06T03:05:16Z")

</div>


